[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <4E04B84D.8010001@bonsai-sec.com>
Date: Fri, 24 Jun 2011 13:16:13 -0300
From: Nahuel Grisolia <nahuel@...sai-sec.com>
To: full-disclosure@...ts.grok.org.uk, owasp-argentina@...ts.owasp.org
Subject: ASHX, ASMX or What?
List,
Imagine that you're in front of an """"insecure"""" file upload in the
context of an IIS6,7 (no ;.jpg :P) and the regex filtering the file is like:
[anything].asp[anything] (yeah, my.aspirator.jpg is filtered hehe)
No .aspx, no .asp and no .aspx;jpg even if the server is vulnerable...
So... is there any way to bypass this control? Like uploading a
malicious Webservice (can we simply upload a Webservice file? I think
they need to be precomplied first) or something like that?
Thanks a lot!
regards,
--
Nahuel Grisolia - C|EH
Information Security Consultant
Bonsai Information Security Project Leader
http://www.bonsai-sec.com/
(+54-11) 4777-3107
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists